Trust

Security by default.

A short, honest summary of how we protect your account and data. We're a young company, but we built RunDo with the security baseline that older platforms had to bolt on years later.

AES-256Encryption at rest
TLS 1.3Encryption in transit
72 hrBreach notification
SingaporeData residency

Account security

Your account is the front door. Locked by default.

Firebase Auth

Sign-in handled by Google's auth infrastructure. Industry-standard OAuth, password hashing.

Optional 2FA (TOTP)

Authenticator app codes (Google Authenticator, Authy, 1Password). Owners can require 2FA org-wide.

Session management

See and revoke sessions from any device. Auto-logout after configurable idle time.

Audit log

Every admin action logged with actor, timestamp, before/after state. Exportable.

Infrastructure

Hosted in Singapore

Supabase ap-southeast-1 region. Cloudflare for DNS, CDN, edge security.

Backups

Every 6 hours, retained 30 days, replicated to a second region for disaster recovery.

Encryption

All traffic TLS 1.3. All data at rest AES-256. Vault for sensitive credentials.

Production access

Limited to 2 people. Quarterly access review. SSH keys + 2FA required.

Compliance roadmap

Where we are today, where we're going.

  1. 01
    Today: PDPA-compliant (Singapore)

    Fully aligned with Singapore's Personal Data Protection Act from day 1. Data residency, breach notification, data subject rights all in place.

  2. 02
    Today: GDPR-aligned (EU)

    Standard Contractual Clauses for cross-border transfers. Data subject rights honoured. DPA available on request.

  3. 03
    Q4 2026: SOC 2 Type 1

    Currently in audit. Expected report Q4 2026.

  4. 04
    2027: SOC 2 Type 2 + ISO 27001

    Multi-year operational evidence required. On track for late 2027.

Ready to run on autopilot?

Drop your email, we'll send your invite as a slot opens.

Get early access